nerdexam
IBM

C1000-141 · Question #62

A user belongs to two security groups: one has a qualified data restriction on the Asset Object while the other grants full access to the Asset application. Which behavior will the user experience?

The correct answer is B. The user will have restricted access to the Asset data. When security groups conflict, data restrictions take precedence over application-level access grants. Even though one group grants full access to the Asset application, the qualified data restriction from the other group filters which Asset records the user can actually…

Security Configuration

Question

A user belongs to two security groups: one has a qualified data restriction on the Asset Object while the other grants full access to the Asset application. Which behavior will the user experience?

Options

  • AThe user will have full access to the Asset data.
  • BThe user will have restricted access to the Asset data.
  • CThe user will only experience the data restriction in the Work Center applications.
  • DThe user will be able to view all Asset records but will only be able to edit those not included in

How the community answered

(50 responses)
  • A
    2% (1)
  • B
    80% (40)
  • C
    6% (3)
  • D
    12% (6)

Explanation

When security groups conflict, data restrictions take precedence over application-level access grants. Even though one group grants full access to the Asset application, the qualified data restriction from the other group filters which Asset records the user can actually interact with - the restriction wins.

Why the distractors are wrong:

  • A is wrong because full application access does not override a data-level restriction; the restriction narrows what data is visible/accessible regardless of app permissions.
  • C is wrong because data restrictions are not limited to Work Center applications - they apply system-wide to the object they target.
  • D is wrong because a qualified data restriction controls access to a filtered subset of records, not a view-all/edit-some split (that would describe a different type of permission).

Memory tip: Think of it as a two-layer gate - the application access lets you into the building, but the data restriction is a second lock on the filing cabinet inside. Having a key to the building doesn't unlock the cabinet. Restrictions always win.

Topics

#security groups#data restriction#permission precedence#access control

Community Discussion

No community discussion yet for this question.

Full C1000-141 Practice